Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2025-58405 — Lack of protection mechanisms against Clickjacking attacks

The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an…

Remote | Cross-Site Request Forgery
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
7.1 HIGH
CVE-2025-58402 — Insecure Direct Object Reference Message ID

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages…

Remote | Authorization
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
6.9 MEDIUM
CVE-2025-30062 — SQL injection in CheckUnitCodeAndKey.pl

In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.

| Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.4 CRITICAL
CVE-2025-30044 — RCE on uhcapache user permissions

In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlogstat2.pl", and "/cgi-bin/CliniNET.prd/utils/dblog…

| Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.0 CRITICAL
CVE-2025-30042 — Session generation possible with certificate number only

The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verifica…

| Authentication
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.0 CRITICAL
CVE-2025-30035 — Lack of API authentication allowing session generation for any user

The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any oth…

| Authentication
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
8.8 HIGH
CVE-2025-10350 — SQL injection in CGM NETRAAD

SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GC…

| Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2026-2584 — SQL Injection in Ciser System SL firmware

A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthenticated, remote attacker (AV:N/PR:N) can exploit this flaw by sending speciall…

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
4.4 MEDIUM
CVE-2026-20445 — MDDP System Crash Vulnerability (Denial of Service)

In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not n…

android mt6835 mt6855 mt6878 mt6879 mt6883 +18 more | Remote | Race Condition
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.7 MEDIUM
CVE-2026-20444 — Apple Safari Memory Corruption Privilege Escalation

In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User …

android mt6781 mt6789 mt6833 mt6835 mt6853 +41 more | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.7 MEDIUM
CVE-2026-20443 — Apache HTTP Server Use After Free Memory Corruption Vulnerability

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interact…

android mt6781 mt6789 mt6833 mt6835 mt6853 +41 more | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.4 MEDIUM
CVE-2026-20442 — Microsoft Windows Display Use After Free Local Denial of Service

In display, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not …

android mt6781 mt6789 mt6833 mt6835 mt6853 +41 more | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.7 MEDIUM
CVE-2026-20441 — MAE Out-of-Bounds Write Vulnerability

In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User in…

android mt8678 mt6899 mt6991 mt2718 mt8793 | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.7 MEDIUM
CVE-2026-20440 — "MAE Out-of-Bounds Write Local Privilege Escalation Vulnerability"

In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User in…

android mt8678 mt6899 mt6991 mt2718 mt8793 | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.4 MEDIUM
CVE-2026-20439 — Windows imgsys Use-After-Free Vulnerability

In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not n…

android mt8678 mt6899 mt6991 mt2718 mt8793 | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.4 MEDIUM
CVE-2026-20438 — MAE Out-of-Bounds Write Vulnerability

In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interact…

android mt8168 mt8188 mt8678 mt8695 mt8169 +6 more | Race Condition
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.4 MEDIUM
CVE-2026-20437 — MAE Use-After-Free System Crash Vulnerability

In MAE, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not need…

android mt8678 mt6899 mt6991 mt2718 mt8793 | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.7 MEDIUM
CVE-2026-20436 — "Qualcomm WLAN STA Driver Privilege Escalation Vulnerability"

In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System pr…

nbiot_sdk mt7902 mt7921 mt7927 mt7920 mt7922 +2 more | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.6 MEDIUM
CVE-2026-20435 — Samsung Preloader Device Unique Identifier Read Vulnerability

In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no ad…

android openwrt yocto rdk-b zephyr mt6781 +34 more | Information Disclosure
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.5 HIGH
CVE-2026-20434 — Huawei Modem Out-of-Bounds Write Privilege Escalation Vulnerability

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the att…

lr13 nr15 nr16 nr17 lr12a mt2735 +93 more | Memory Corruption
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
Showing 20 of 4863 Results